IP Library Granted Patent US 7,756,981
Granted Patent B2
US 7,756,981 · App. 11/556,470 · Granted Jul 13, 2010

Systems and methods for remote rogue protocol enforcement

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,756,981
App. No.
11/556,470
Granted
Jul 13, 2010
Kind
B2
Abstract

A user agent residing within a remote client and configured to enforce message protocol policy is disclosed. The user agent includes a communications monitoring element that examines a communications connection between the client and an external message server to determine if the message server matches a restricted server attribute. The user agent also includes a communications controller element that works with the communications monitoring element to block communications between the client and the message server when the message server matches a restricted server attribute unless the communications are monitored by a protocol inspection gateway. The gateway intercepts the communications between the client and the message server and inspects a message protocol associated with the intercepted communications to determine if the message protocol matches a protocol definition file, and when a match occurs, apply a policy enforcement rule that overrides aspects of the message protocol associated with the intercepted communications.

Claims (51)

1. A system configured to enforce message protocol policy, the system comprising:

a virtual private network agent residing within a remote client;

a user agent residing within the remote client, the user agent comprising,

a communications monitoring element executing on a computing device and configured to examine a communications connection between the remote client and an external message server to determine if an attribute of the external message server matches a restricted server attribute, wherein both the remote client and the external message server reside outside an enterprise network comprising a virtual private network gateway and a protocol inspection gateway; and

a communications controller element configured to work in conjunction with the communications monitoring element to,

block instant message communications between the remote client and the external message server when the attribute of the external message server matches the restricted server attribute unless the instant message communications between the remote client and the external message server and route the blocked instant message communications via the virtual private network agent to the enterprise network, and

allow direct communication between the remote client and the external message server by bypassing the virtual private network agent when the attribute of the external message server does not match the restricted server attribute;

wherein the virtual private network gateway is configured to communicate with the virtual private network agent to receive the instant message communications routed thereto, wherein the virtual private network gateway is further configured to receive the routed instant message communications from the virtual private network agent via tunneling,

and wherein the protocol inspection gateway is configured to,

receive the instant message communications from the virtual private network gateway routed to the enterprise network,

inspect a message protocol associated with the routed instant message communications to determine if the message protocol matches a protocol definition file, and

when a match occurs, apply applying a policy enforcement rule associated with the protocol definition file that overrides aspects of the message protocol associated with the routed instant message communications.

2. The system as recited in claim 1 , wherein the restricted server attribute comprises one or more internet protocol (IP) addresses of one or more instant messaging servers.

3. The system recited in claim 1 , wherein applying the policy enforcement rule comprises terminating a communication connection associated with the routed instant message communications.

4. The system recited in claim 1 , wherein applying the policy enforcement rule comprises recording information associated with the routed instant message communications.

5. The system recited in claim 1 , wherein applying the policy enforcement rule comprises creating a log comprising information associated with the routed instant message communications and any related communications.

6. A system for enforcing message protocol policy for a remote client, the system comprising:

a virtual private network agent residing within a remote client, the virtual private network agent configured to function as a communications proxy for the remote client;

a user agent executing on a computing device and residing within the remote client, the user agent configured to examine every communications connection established between the remote client and an external message server to determine whether an attribute of the external message server matches a restricted server attribute, and the user agent being further configured to,

when a match occurs, route to the virtual private network agent instant messages to be transmitted between the remote client and the external message server, and

when a match does not occur, allow direct communication between the remote client and the external message server by bypassing the virtual private network agent; and an enterprise network communicatively connected to the remote client and the external message server, wherein both the remote client and the external message server reside outside the enterprise network, the enterprise network including,

a virtual private network gateway configured to communicate with the virtual private network agent to receive the instant messages routed thereto, wherein the virtual private network gateway is further configured to receive the routed instant messages from the virtual private network agent via tunneling; and

a protocol inspection gateway communicatively connected to the virtual private network gateway and the external message server, the protocol inspection gateway configured to,

receive the instant messages from the virtual private network gateway,

inspect a message protocol associated with each received instant message to determine if the message protocol matches a protocol definition file, and

when a match occurs, apply a policy enforcement rule associated with the protocol definition file that overrides aspects of the message protocol associated with the received instant message.

7. The system of claim 6 , wherein the restricted server attribute comprises one or more internet protocol (IP) addresses of one or more instant messaging servers.

8. The system of claim 6 , wherein applying the policy enforcement rule comprises terminating a communication connection associated with the received instant messages.

9. The system of claim 6 , wherein applying the policy enforcement rule comprises recording information associated with the received instant messages.

10. The system of claim 6 , wherein applying the policy enforcement rule comprises creating a log comprising information associated with the intercepted instant messages and any related messages.

11. The system of claim 6 , wherein at least one of the remote client and the external message server is communicatively coupled to the enterprise network via a public internet.

12. The system of claim 6 , wherein the virtual private network agent and the virtual private network gateway comprise a virtual private network.

13. The system of claim 6 , wherein functionalities of the virtual private network gateway and the protocol inspection gateway are integrated into one network gateway device.

14. A method for enforcing message protocol policy for a remote client, the method comprising:

establishing a communication connection between a remote client and an external message server, wherein both the remote client and the external message server are located outside an enterprise network;

inspecting, with a user agent executing on a computing device of the remote client, the communications connection between the remote client and the external message server to determine if a selected attribute of the external message server matches a restricted server attribute;

when a match occurs, (i) blocking instant messages to be sent via the communications connection between the remote client and the external message server (ii) fill routing the blocked instant messages with a virtual private network agent of the remote client to a virtual private network gateway via tunneling, and (iii) communicating the routed instant messages from the virtual private network gateway to a protocol inspection gateway within the enterprise network, wherein the protocol inspection gateway is configured to,

inspect a message protocol associated with the routed instant message to determine if the message protocol matches a protocol definition file, and

when a match occurs, apply a policy enforcement rule associated with the protocol definition file that overrides aspects of the message protocol associated with the routed instant message, and

when a match does not occur between the selected attribute of the external message server and the restricted server attribute, allowing direct communication between the remote client and the external message server by bypassing the virtual private network agent and the virtual private network gateway.

15. The method of claim 14 , wherein the restricted server attribute comprises one or more internet protocol (IP) addresses of one or more instant messaging servers.

16. The method of claim 14 , wherein applying the policy enforcement rule comprises terminating a communication connection associated with the routed instant messages.

17. The method of claim 14 , wherein applying the policy enforcement rule comprises recording information associated with the routed instant messages.

18. The method of claim 14 , wherein applying the policy enforcement rule comprises creating a log comprising information associated with the routed instant messages and any related messages.

19. The user agent of claim 1 , wherein the restricted server attribute comprises a message server type.

20. The user agent of claim 1 , further comprising a system configuration file for identifying one or more restricted server attributes.

21. The user agent of claim 20 , wherein the system configuration file is stored on the remote client.

22. The user agent of claim 1 , wherein the communications monitoring element is configured to receive the restricted server attribute from a computing device on the enterprise network.

23. The system of claim 6 , wherein the direct communication between the remote client and the external message server comprises an unsecured communications connection.

24. The method of claim 14 , additionally comprising maintaining a list on the remote client of one or more restricted server attributes.

25. The method of claim 24 , additionally comprising updating the list when the remote client accesses the enterprise network.

Assignments (32)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044800/0848 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040040/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0618 →
RELEASE OF SECURITY INTEREST Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL MARKETING L.P.; ASAP SOFTWARE EXPRESS, INC.; APPASSURE SOFTWARE, INC.; COMPELLANT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL PRODUCTS L.P.; DELL USA L.P.; DELL SOFTWARE INC.; FORCE10 NETWORKS, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 040065/0216 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Jan 2, 2014
From: APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 031897/0348 →
PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 031899/0261 →
PATENT SECURITY AGREEMENT (ABL) Recorded Jan 2, 2014
From: DELL INC.; APPASSURE SOFTWARE, INC.; ASAP SOFTWARE EXPRESS, INC.; BOOMI, INC.; COMPELLENT TECHNOLOGIES, INC.; CREDANT TECHNOLOGIES, INC.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL USA L.P.; FORCE10 NETWORKS, INC.; GALE TECHNOLOGIES, INC.; PEROT SYSTEMS CORPORATION; SECUREWORKS, INC.; WYSE TECHNOLOGY L.L.C.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 031898/0001 →
RELEASE OF SECURITY INTEREST Recorded Sep 20, 2013
From: MENLO VENTURES IX, L.P.; MENLO ENTREPRENEURS FUND IX, L.P.; MENLO ENTREPRENEURS FUND IX(A), L.P.; MMEF IX, L.P.; PALOMAR VENTURES II, L.P.; WINDWARD VENTURES 2000, L.P.; WINDWARD VENTURES 2000-A, L.P.; MISSION VENTURES II, L.P.; MISSION VENTURES AFFILIATES II, L.P.; GC&H INVESTMENTS, LLC; PERFORMANCE DIRECT INVESTMENTS I, L.P.; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-127; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-128; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-129; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-130
To: AKONIX SYSTEMS, INC.
Reel/Frame 031247/0495 →
CHANGE OF NAME Recorded Aug 20, 2013
From: QUEST SOFTWARE, INC.
To: DELL SOFTWARE INC.
Reel/Frame 031043/0281 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Sep 28, 2012
From: WELLS FARGO CAPITAL FINANCE, LLC (FORMERLY KNOWN AS WELLS FARGO FOOTHILL, LLC)
To: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
Reel/Frame 029050/0679 →
PATENT SECURITY AGREEMENT Recorded Feb 18, 2009
From: QUEST SOFTWARE, INC.; AELITA SOFTWARE CORPORATION; SCRIPTLOGIC CORPORATION; VIZIONCORE, INC.; NETPRO COMPUTING, INC.
To: WELLS FARGO FOOTHILL, LLC
Reel/Frame 022277/0091 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2008
From: AKONIX SYSTEMS, INC.
To: QUEST SOFTWARE, INC.
Reel/Frame 022000/0781 →
SECURITY AGREEMENT Recorded May 13, 2008
From: AKONIX SYSTEMS, INC.
To: MENLO VENTURES IX, L.P.; MENLO ENTREPRENEURS FUND IX, L.P.; MENLO ENTREPRENEURS FUND IX(A), L.P.; MMEF IX, L.P.; PALOMAR VENTURES II, L.P.; WINDWARD VENTURES 2000, L.P.; WINDWARD VENTURES 2000-A, L.P.; MISSION VENTURES II, L.P.; MISSION VENTURES AFFILIATES II, L.P.; GC&H INVESTMENTS, LLC; PERFORMANCE DIRECT INVESTMENTS I, L.P.; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-127*; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-128*; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-129*; FIRST PLAZA GROUP TRUST, SOLELY FOR THE BENEFIT OF POOL PMI-130*
Reel/Frame 020940/0518 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2007
From: SHASTRI, VIJNAN; LEE, LISA; TRAN, TRUNG
To: AKONIX SYSTEMS, INC.
Reel/Frame 018832/0104 →